Skip to content

Remediate current Dependabot security alerts #45

Description

@KHAEntertainment

Summary

Dependabot has flagged 7 open security vulnerabilities (2 critical, 5 medium). All affected dependencies are in upstream SGLang code (sgl-model-gateway/ and docs/), not Engram fork additions.

Critical: google.golang.org/grpc auth bypass (CVE-2026-33186) in 2 Go modules
Medium: 3 wasmtime CVEs + jsonwebtoken type confusion in Cargo.toml, urllib3 redirect bypass in docs/requirements.txt

Full alert details: https://github.com/Clarit-AI/Engram/security/dependabot

Action Plan

  1. Wait for the Q2 upstream sync (⚠️ Upstream sync blocked — 243 commits, merge conflicts #41) to land. It may resolve some or all of these.
  2. Re-check Dependabot after merge. Patch whatever remains.
  3. Single remediation PR for all remaining alerts.

Detailed remediation instructions and agent context tracked in Linear KHA-252.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions